Hortonworks Data Platform

Apache Knox Gateway Administrator Guide

2014-07-02


Contents

1. Knox Gateway Overview
1. Knox Gateway Network Architecture
1.1. Supported Hadoop Services
2. Configure the Knox Gateway
1. Secure the Gateway Directories
2. Customize the Gateway Port and Path
3. Manage the Master Secret
3.1. Setting the Master Secret
3.2. Change the Master Secret
4. Manually Redeploy Cluster Topologies
4.1. Redeploy all Clusters
4.2. Redeploy Specific Clusters
5. Manually start and stop Knox
5.1. Manually start Knox
5.2. Manually start the after an Unclean Shutdown
5.3. Manually stop Knox
3. Define Cluster Topology
4. Configure the Hadoop Cluster Services
1. Set up Hadoop Service URLs
2. Example of Service Definitions
3. Validate Service Connectivity
5. Map the Internal Nodes to External URLs
1. Set up a Hostmap Provider
2. Example of an EC2 Hostmap Provider
3. Example of Sandbox Hostmap Provider
4. Enable Hostmap Debugging
6. Set up LDAP Authentication
1. Advanced LDAP Configuration
1.1. Saving the LDAP Password in the Credential Store
2. Example of an Active Directory Configuration
3. Example of an OpenLDAP Configuration
4. Testing an LDAP Provider
7. Set up HTTP Header Authentication for Federation/SSO
1. Example of SiteMinder Configuration
2. Testing an HTTP Header Tokens
8. Configure Identity Assertion
1. Structure of the Identity-Assertion Provider
2. Set up Basic Identity Assertion
3. Map Effective User to Cluster User
3.1. Example of User Mapping
4. Map Effective Users to Groups
4.1. Configure Group Mappings
4.2. Examples of Group Mapping
9. Configure Service Level Authorization
1. Set up an Authorization Provider
2. Examples of Authorization
10. Audit Gateway Actitivity
1. Audit Log Fields
2. Change Roll Frequency of the Audit Log
11. Gateway Security
1. Implement Web Application Security
1.1. Configure Protection Filter against Cross Site Request Forgery Attacks
1.2. Validate CSRF Filtering
2. Configure Knox with a Secured Hadoop Cluster
2.1. Configure Knox Gateway on the Hadoop Cluster
2.2. Add Knox Principal to KDC
2.3. Configure Knox Gateway for Keberos
3. Configure Wire Encryption (SSL)
3.1. Using Self-Signed Certificate for Evaluations
3.2. CA-signed Certificates for Production
3.3. Set up Trust for the Knox Gateway Clients
4. Set up for Oozie Server with SSL
12. Logs and Troubleshooting Steps
1. Knox Gateway Logs
1.1. Changing the Log Level
2. Use Sample Scripts to Test Connectivity and Functionality
3. LDAP Connectivity Issues
3.1. Increase Log Level and Test
3.2. Test LDAP Connection
3.3. LDAP Basic Troubleshooting

loading table of contents...